Various Data Subject Access Request (DSAR) processing systems are adapted for presenting a first webform on a first web site, the first webform being adapted to receive DSAR's and to route the requests to a first designated individual for processing; presenting a second webform on a second web site, the second webform being adapted to receive DSAR's and to route the requests to a second designated individual for processing; receiving, via the first webform, a first DSAR; at least partially in response to the receiving the first DSAR, automatically routing the first DSAR to the first designated individual for handling; receiving, via the second webform, a second DSAR; at least partially in response to the receiving the second DSAR, automatically routing the second DSAR to the second designated individual for handling; and communicating a status of both the first DSAR and the second DSAR via a single user interface.
Legal claims defining the scope of protection, as filed with the USPTO.
1. A data subject access request management system comprising: one or more processors; and computer memory, wherein the data subject access request management system is configured for: receiving a plurality of data subject access requests, each of the plurality of data subject access requests being a request for a particular organization to take one or more actions with regard to one or more pieces of personal data that the particular organization has previously obtained on a respective data subject associated with each of the plurality of data subject access requests; at least partially in response to receiving the plurality of data subject access requests, obtaining metadata regarding the respective data subject of each of the plurality of data subject access requests; using the metadata to determine a priority of each particular data subject access request of the plurality of data subject access requests based on the obtained metadata, wherein the metadata is selected from the group consisting of: (1) a request type associated with each particular data subject access request; (2) the location from which each particular data subject access request is being made; (3) one or more current sensitivities to world events; and (4) a status of the respective data subject issuing each particular data subject access request; and fulfilling each particular data subject access request according to the determined priority of the DSAR by: determining a designated individual to handle each particular data subject access request based at least in part on the determined priority; and at least partially in response to determining the designated individual to handle each particular data subject access request, automatically routing each particular data subject access request to the designated individual for handling; determining, by the one or more processors, whether one or more portions of each particular data subject access request are configured for automatic processing; and in response to determining that the one or more portions are configured for automatic processing, automatically processing the one or more portions.
2. The data subject access request management system of claim 1 , wherein: the metadata comprises the request type associated with each particular data subject access request; and the request type is selected from the group consisting of: a first request to delete one or more pieces of personal data associated with the respective data subject stored on one or more computer systems associated with a particular organization; a second request to provide the one or more pieces of personal data associated with the respective data subject stored on the one or more computer systems associated with the particular organization.
3. The data subject access request management system of claim 1 , wherein the metadata comprises the location from which each particular data subject access request is being made.
4. The data subject access request management system of claim 1 , wherein the metadata comprises the one or more current sensitivities to world events.
5. The data subject access request management system of claim 1 , wherein the metadata comprises the status of the respective data subject issuing each particular data subject access request.
6. The data subject access request management system of claim 5 , wherein the status of the respective data subject issuing each particular data subject access request comprises a customer loyalty of each respective data subject.
7. The data subject access request management system of claim 1 , wherein the data subject access request management system is further configured for: communicating, via a single user interface, a status of each of the plurality of data subject access requests.
8. A data subject access request management system comprising: one or more processors; and computer memory, wherein the data subject access request management system is configured for: presenting a first webform on a first website, the first webform being structured to receive data subject access requests that are to be routed to a first designated individual for processing; presenting a second webform on a second website, the second webform being structured to receive data subject access requests; receiving, via the first webform, a first data subject access request, the first data subject access request being a request for a particular organization to take one or more actions with regard to one or more first pieces of personal data that the particular organization has previously obtained on a first data subject associated with the first data subject access request; at least partially in response to the receiving the first data subject access request, automatically routing the first data subject access request to the first designated individual for handling; determining whether one or more portions of the first data subject access request are suitable for automatic handling; and in response to determining that the one or more portions is suitable for automatic handling, automatically processing the one or more portions; receiving, via the second webform, a second data subject access request, the second data subject access request being a request for the particular organization to take one or more actions with regard to one or more second pieces of personal data that the particular organization has previously obtained on a second data subject associated with the second data subject access request; at least partially in response to the receiving the second data subject access request: identifying a second designated individual for handling the second data success request based at least in part on one or more pieces of information provided as part of the second data access request submitted via the second webform; and automatically routing the second data subject access request to the second designated individual for handling; and after receiving the first data subject access request, facilitating at least one action selected from a group consisting of: (a) verifying that the first data subject access request was submitted by the first data subject associated with the first data subject access request; (b) assigning the first data subject access request to a third designated individual for handling; (c) requesting an extension to fulfill the first data subject access request; (d) rejecting the first data subject access request; and (e) suspending the first data subject access request.
9. The data subject access request management system of claim 8 , wherein the data subject access request management system is further configured for: providing a webform creation tool that is adapted for receiving webform creation criteria from a particular user, the webform creation criteria comprising at least one criterion from a group consisting of: (1) a language that the form will be displayed in; (2) what information is to be requested from data subjects who use the webform to initiate a data subject access request; and (3) a routing mechanism for determining how data subject access requests that are received via the webform will be routed; and executing the webform creation tool to create both the first webform and the second webform.
10. The data subject access request management system of claim 9 , wherein: the webform creation criteria comprises the routing mechanism for determining how data subject access requests that are received via the webform will be routed; and the routing mechanism is selected from the group consisting of: a first mechanism for routing the data subject access requests that are received via the webform to a particular designated individual; and a second mechanism for identifying a designated individual for handling the data subject access requests that are received via the webform based at least in part on one or more pieces of information associated with each data subject access request of the data subject access requests that are received via the webform.
11. The data subject access request management system of claim 10 , wherein: the routing mechanism comprises the second mechanism for identifying the designated individual for handling the data subject access requests that are received via the webform; and the one or more pieces of information associated with each data subject access request of the data subject access requests that are received via the webform comprise one or more pieces of information provided as part of each data subject access request submitted via the webform.
12. The data subject access request management system of claim 11 , wherein the data subject access request management system is further configured for: automatically verifying an identity of a particular data subject access requestor placing the second data subject access request; at least partially in response to verifying the identity of the particular data subject access requestor, automatically obtaining at least a portion of information requested in the second data subject access request; and after obtaining the at least a portion of the requested information, displaying the obtained information to a user as part of a fulfillment of the second data subject access request.
13. The data subject access request management system of claim 9 , wherein the data subject access request management system is further configured for: at least partially in response to receiving the first data subject access request and the second data subject access request, obtaining metadata regarding a first data subject associated with the first data subject access request and a second data subject associated with the second data subject access request; and using the metadata to determine a priority of each of the first data subject access request and the second data subject access request based on the obtained metadata, wherein the metadata is selected from the group consisting of: (1) a request type associated with each of first data subject access request and the second data subject access request; (2) a respective location from which each of the first data subject access request and the second data subject access request were made; (3) one or more current sensitivities to world events; and (4) a status of the first data subject and the second data subject.
14. The data subject access request management system of claim 13 , wherein the data subject access request management system is further configured for: automatically verifying an identity of the second data subject; and at least partially in response to verifying the identity of the second data subject, automatically processing the second data access request to opt out of having a first organization that is associated with the second webform use personal information associated with the second data subject in one or more particular ways.
15. The data subject access request management system of claim 13 , wherein the data subject access request management system is further configured for: automatically verifying an identity of the first data subject; and at least partially in response to verifying the identity of the first data subject, automatically facilitating the deletion of personal data of the first data subject that is being stored by a second organization associated with the first webform.
16. The data subject access request management system of claim 9 , wherein the data subject access request management system is further configured for enabling the first designated individual to request an extension to fulfill the first data subject access request.
17. The data subject access request management system of claim 16 , wherein the data subject access request management system is further configured for communicating, via a single user interface, a status of each of the first data subject access request and the second data subject access request.
18. A data subject access request management system comprising: one or more processors; and computer memory, wherein the data subject access request management system is configured for: receiving a first plurality of data subject access requests via a first webform, each of the first plurality of data subject access requests being a request for a particular organization to take one or more actions with regard to one or more pieces of personal data that the particular organization has previously obtained on a respective data subject associated with each of the first plurality of data subject access requests; at least partially in response to receiving the first plurality of data subject access requests, obtaining first metadata regarding a first respective data subject of each of the first plurality of data subject access requests; using the metadata to determine a priority of each first particular data subject access request of the first plurality of data subject access requests based on the obtained first metadata, wherein the first metadata is selected from the group consisting of: (1) a first request type associated with each particular first data subject access request; (2) a first respective location from which each first particular data subject access request is being made; (3) one or more current sensitivities to world events; and (4) a first respective status of the respective first data subject issuing each particular first data subject access request; and fulfilling each particular first data subject access request according to the determined priority of the first plurality of data subject access requests by: determining a designated individual to handle each particular first data subject access request based at least in part on the determined priority; and at least partially in response to determining the designated individual to handle each particular first data subject access request, automatically routing each particular first data subject access request to the designated individual for handling; determining whether one or more portions of each particular first data subject access request are configured for automatic processing; and in response to determining that the one or more portions are configured for automatic processing, automatically processing the one or more portions.
19. The data subject access request management system of claim 18 , wherein the data subject access request management system is further configured for: receiving a second plurality of data subject access requests via a second webform; at least partially in response to receiving the second plurality of data subject access requests, obtaining second metadata regarding a second respective data subject of each of the second plurality of data subject access requests; using the metadata to determine a priority of each second particular data subject access request of the second plurality of data subject access requests based on the obtained second metadata, wherein the second metadata is selected from the group consisting of: (1) a second request type associated with each particular second data subject access request; (2) a second respective location from which each second particular data subject access request is being made; (3) the one or more current sensitivities to world events; and (4) a second respective status of the respective second data subject issuing each particular second data subject access request; and fulfilling each particular second data subject access request according to the determined priority of the second plurality of data subject access requests by: determining a designated individual to handle each particular second data subject access request based at least in part on the determined priority; and at least partially in response to determining the designated individual to handle each particular second data subject access request, automatically routing each particular second data subject access request to the designated individual for handling.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
March 9, 2020
December 15, 2020
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.